TwistedHelixis Posted December 3, 2019 Posted December 3, 2019 I would like advanced device policy setup on all the school owned Android tablets but not on staff personal phones etc. Currently the basic policy is being applied for anyone that logs in using a school domain account. Is it possible to apply the advanced device policy just to tablets the school owns?
Zoom7000 Posted December 3, 2019 Posted December 3, 2019 I would like advanced device policy setup on all the school owned Android tablets but not on staff personal phones etc. Currently the basic policy is being applied for anyone that logs in using a school domain account. Is it possible to apply the advanced device policy just to tablets the school owns? Could this possibly be achieved by putting the school devices in to their own OU in the Admin Console and then applying the advanced policy to that OU?
Garacesh Posted December 3, 2019 Posted December 3, 2019 Could this possibly be achieved by putting the school devices in to their own OU in the Admin Console and then applying the advanced policy to that OU? This is what we do with our Chromebooks. If a pupil or a member of staff wants to go and buy their own Chromebook, they can, and they can login without enrolling it to our domain. Doing this, they only receive the User settings and not the Device settings they'd get on a school Chromebook. The school-owned devices, though, get enrolled as part of the domain and additional settings are applied. Same applies to Android phones. We don't actually have any 'school' phones/tablets on the domain (though it's on my to-do list) but if they connect their G Suite account to an Android device it forces them to download and apply the Device Policy (because of the user settings) before it'll start syncing.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 Could this possibly be achieved by putting the school devices in to their own OU in the Admin Console and then applying the advanced policy to that OU? This is what we do with our Chromebooks. But how? If I open device management > setup > Enable Mobile Management, there is no option to apply that setting to an OU or group.
Garacesh Posted December 3, 2019 Posted December 3, 2019 Device management, Chrome management, Device Settings You can select your OU's from there and apply settings accordingly.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 Ohhh it's because my test domain is G Suite for business, which is missing the device by OU stuff in the educational version, good grief.
Garacesh Posted December 3, 2019 Posted December 3, 2019 Ohhh it's because my test domain is G Suite for business, which is missing the device by OU stuff in the educational version, good grief. .... I... er.. genuinely didn't realise there were any differences. I thought they just slapped a different label on it and changed the pricing
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 Nope still doesn't make sense. Device management, Chrome management, Device Settings These are not Chrome devices, but tablets. Could this possibly be achieved by putting the school devices in to their own OU in the Admin Console and then applying the advanced policy to that OU? How do I put a device in an OU? I seem to be only able to put users in to an OU.
Garacesh Posted December 3, 2019 Posted December 3, 2019 How do I put a device in an OU? I seem to be only able to put users in to an OU. It's been a while since I've done it, but Devices can definitely go into their own OU's, since they have to exist somewhere within the organisation structure in order to apply policies. I have a feeling that this might only apply to chrome devices, though. And I'm not sure if 'chrome devices' includes Android tablets.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 So I can apply advanced profile to an OU with users in, but what if that user also has a personal device that I don't want them to have advanced policy installed on.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 I have a feeling that this might only apply to chrome devices, though. ill give that a test then, and get back
Garacesh Posted December 3, 2019 Posted December 3, 2019 So I can apply advanced profile to an OU with users in, but what if that user also has a personal device that I don't want them to have advanced policy installed on. To be honest, I split my users and devices into different OU's, specifically because we have staff and pupils using their own personal devices, so I'm not sure I can give any more info that'll be helpful.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 To be honest, I split my users and devices into different OU's, specifically because we have staff and pupils using their own personal devices, so I'm not sure I can give any more info that'll be helpful. There is no option for tablets under the Chrome device pages, so that's a no go. For the moment I will just apply advanced profile to the pupils OU, and keep trying to workout how I can apply policies to specific tablets. Cheers
Garacesh Posted December 3, 2019 Posted December 3, 2019 (edited) I don't know if this'll help, but if you try to connect one of our G Suite accounts to an Android device, you're forced to download the Device Policy app and set it as a Device Administrator first. There are some Android devices settings (Devices, Android Settings) that I assume are controlled by the Device Policy app. It might be a place to start if you're looking to configure settings. But this doesn't directly control the device. It's weird, but I'll try and explain it as best I can. The Device Policy app must be installed and set as a Device Administrator in order to use an organisational G Suite account. This app can then be uninstalled, or have its administrative privileges removed. However, doing this will then lock the user out of the G Suite account on that device until everything is restored as it should be (app installed, Admin set). So it's not really a device policy. It's a 'these settings are required before you can use this account on this device' policy. Now there's also something mentioned in Android Settings about 'company owned devices'. I don't know if that's a separate thing or if it just assumes any device enrolled into the domain (like a Chromebook) is a 'company owned device'. It's possible that if you remove the ability to control apps (Android Settings, Apps and Data Sharing, Apps Settings: Allow controlling installed applications.) you could manually install the device policy and then it would stop the user(s) uninstalling it. But I'm not sure. Edited December 3, 2019 by Garacesh
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 The Device Policy app must be installed and set as a Device Administrator in order to use an organisational G Suite account. What I have worked out is this is not always the case. I have just logged in to another device using my G Suite account and did not need the policy app. I think the reason I did not need it was a) I have the policy set to basic, b) I am using a new version of Android.
TwistedHelixis Posted December 3, 2019 Author Posted December 3, 2019 I wish I could just use the list of devices that have accessed the domain and then assign them a profile, that would be far simpler
Garacesh Posted December 3, 2019 Posted December 3, 2019 did not need the policy app. I think the reason I did not need it was a) I have the policy set to basic Yep, that's probably why. I'm using the latest version of Android on my phone and I still have to use Device Policy. There's also some talk about Android Management API? Maybe that's worth a look?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now